VYPR

CWE-190

Integer Overflow or Wraparound

BaseStableLikelihood: Medium

Description

The product performs a calculation that can produce an integer overflow or wraparound when the logic assumes that the resulting value will always be larger than the original value. This occurs when an integer value is incremented to a value that is too large to store in the associated representation. When this occurs, the value may become a very small or negative number.

Hierarchy (View 1000)

Parents

Children

Related attack patterns (CAPEC)

CAPEC-92

CVEs mapped to this weakness (3,398)

page 48 of 170
  • CVE-2023-38618HigJan 8, 2024
    risk 0.51cvss 7.8epss 0.00

    Multiple integer overflow vulnerabilities exist in the VZT facgeometry parsing functionality of GTKWave 3.3.115. A specially crafted .vzt file can lead to arbitrary code execution. A victim would need to open a malicious file to trigger these vulnerabilities.This vulnerability…

  • CVE-2023-36916HigJan 8, 2024
    risk 0.51cvss 7.8epss 0.00

    Multiple integer overflow vulnerabilities exist in the FST fstReaderIterBlocks2 chain_table allocation functionality of GTKWave 3.3.115. A specially crafted .fst file can lead to arbitrary code execution. A victim would need to open a malicious file to trigger these…

  • CVE-2023-36915HigJan 8, 2024
    risk 0.51cvss 7.8epss 0.00

    Multiple integer overflow vulnerabilities exist in the FST fstReaderIterBlocks2 chain_table allocation functionality of GTKWave 3.3.115. A specially crafted .fst file can lead to arbitrary code execution. A victim would need to open a malicious file to trigger these…

  • CVE-2023-36864HigJan 8, 2024
    risk 0.51cvss 7.8epss 0.00

    An integer overflow vulnerability exists in the fstReaderIterBlocks2 temp_signal_value_buf allocation functionality of GTKWave 3.3.115. A specially crafted .fst file can lead to arbitrary code execution. A victim would need to open a malicious file to trigger this vulnerability.

  • CVE-2023-35989HigJan 8, 2024
    risk 0.51cvss 7.8epss 0.00

    An integer overflow vulnerability exists in the LXT2 zlib block allocation functionality of GTKWave 3.3.115. A specially crafted .lxt2 file can lead to arbitrary code execution. A victim would need to open a malicious file to trigger this vulnerability.

  • CVE-2023-35057HigJan 8, 2024
    risk 0.51cvss 7.8epss 0.00

    An integer overflow vulnerability exists in the LXT2 lxt2_rd_trace value elements allocation functionality of GTKWave 3.3.115. A specially crafted .lxt2 file can lead to memory corruption. A victim would need to open a malicious file to trigger this vulnerability.

  • CVE-2023-35004HigJan 8, 2024
    risk 0.51cvss 7.8epss 0.00

    An integer overflow vulnerability exists in the VZT longest_len value allocation functionality of GTKWave 3.3.115. A specially crafted .vzt file can lead to arbitrary code execution. A victim would need to open a malicious file to trigger this vulnerability.

  • CVE-2023-35644HigDec 12, 2023
    risk 0.51cvss 7.8epss 0.06

    Windows Sysmain Service Elevation of Privilege Vulnerability

  • CVE-2023-35632HigDec 12, 2023
    risk 0.51cvss 7.8epss 0.07

    Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability

  • CVE-2023-48409HigDec 8, 2023
    risk 0.51cvss 7.8epss 0.00

    In gpu_pixel_handle_buffer_liveness_update_ioctl of private/google-modules/gpu/mali_kbase/mali_kbase_core_linux.c, there is a possible out of bounds write due to an integer overflow. This could lead to local escalation of privilege with no additional execution privileges needed.…

  • CVE-2023-33018HigDec 5, 2023
    risk 0.51cvss 7.8epss 0.00

    Memory corruption while using the UIM diag command to get the operators name.

  • CVE-2023-4295HigNov 7, 2023
    risk 0.51cvss 7.8epss 0.00

    A local non-privileged user can make improper GPU memory processing operations to gain access to already freed memory.

  • CVE-2023-21375HigOct 30, 2023
    risk 0.51cvss 7.8epss 0.00

    In Sysproxy, there is a possible out of bounds write due to an integer underflow. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

  • CVE-2023-38127HigOct 19, 2023
    risk 0.51cvss 7.8epss 0.01

    An integer overflow exists in the "HyperLinkFrame" stream parser of Ichitaro 2023 1.0.1.59372. A specially crafted document can cause the parser to make an under-sized allocation, which can later allow for memory corruption, potentially resulting in arbitrary code execution. An…

  • CVE-2023-36593HigOct 10, 2023
    risk 0.51cvss 7.8epss 0.01

    Microsoft Message Queuing (MSMQ) Remote Code Execution Vulnerability

  • CVE-2023-43787HigOct 10, 2023
    risk 0.51cvss 7.8epss 0.00

    A vulnerability was found in libX11 due to an integer overflow within the XCreateImage() function. This flaw allows a local user to trigger an integer overflow and execute arbitrary code with elevated privileges.

  • CVE-2023-38150HigSep 12, 2023
    risk 0.51cvss 7.8epss 0.01

    Windows Kernel Elevation of Privilege Vulnerability

  • CVE-2023-38142HigSep 12, 2023
    risk 0.51cvss 7.8epss 0.07

    Windows Kernel Elevation of Privilege Vulnerability

  • CVE-2023-36792HigSep 12, 2023
    risk 0.51cvss 7.8epss 0.01

    Visual Studio Remote Code Execution Vulnerability

  • CVE-2023-4734HigSep 2, 2023
    risk 0.51cvss 7.8epss 0.01

    Integer Overflow or Wraparound in GitHub repository vim/vim prior to 9.0.1846.